Launch a new FortiSandbox AWS instance
You can deploy FortiSandbox VM using the AWS GUI.
Launch FortiSandbox instance on AWS using GUI
Starting in version 5.0.0, FortiSandbox supports two Guest VM running modes: Nested and Non-Nested. For more information, see Configure Guest VM Running mode in Configure AWS Config Settings. |
To deploy FortiSandbox on AWS with the GUI:
- You can create your FortiSandbox instance on AWS in On-Demand mode or BYOL mode. For BYOL mode, a FSA-VM00 license file should be purchased and uploaded.
Choose an Amazon Machine Image (AMI)
- Go to EC2 > Instances and click Launch Instance.
- On the Launch an instance page, browse for the FortiSandbox AMI on AWS Marketplace
- Select Fortinet FortiSandbox Advanced Threat Protection (BYOL) or Fortinet FortiSandbox Advanced Threat Protection (On-Demand).
Configure the instance
Add Name and tags
Add descriptive name tags to identify this FortiSandbox instance.
Choose the Instance type
To choose the instance type, refer to the Minimum system requirements.
The AWS instance will be launched as Nested mode if the chosen instance type supports nested virtualization, for example x86_64 metal instance.
Create a new key pair
You do not need to complete this task if you are using an existing key pair. |
To create a new key pair:
- Click Create new key pair.
- In the Create key pair box, enter the Key pair name, then click Create key pair. The key pair downloads automatically.
- Save the key pair on your device.
Edit Network settings
To edit the network settings:
- Configure the following Network Settings:
VPC Select the FortiSandbox VPC you created.
Subnet Select the management interface subnet you created. Auto-Assign public IP Disable. Firewall (security groups) Choose the security group you created. - Configure the following Advanced network configuration settings and click Add network interface.
Configure storage
Fortinet recommends allotting 500GB to 16TB for storage size, depending on the number of historical jobs you want to keep in the system.
(Optional) Advanced details
From v5.0.0, you can enable IMDS v2:
- Metadata accessible: select Enabled
Metadata accessible | Select Enabled. |
Metadata version | Select V2 only (token required) |
Launch the instance
To launch the instance:
- Review the summary, then click Launch instance.
- Click View Instances to view the instance state. Allow several minutes for Status Checks to change from Initializing to 2/2 checks passed.
- Monitor the initialization, and select the created instance. Right-click the instance and select Monitor and troubleshoot > Get Instance Screenshot to view the status of the launched instance.